Privacy Notice

Last updated 7 October 2026

This notice explains how Ministry Memos (“we”, “us”) collects, uses and protects personal data when you use our governance platform. We act as a data processor for the church or charity data you upload, and as a data controller for the account and billing data needed to run the service. We comply with the UK GDPR and the Data Protection Act 2018.

Who we are

Ministry Memos provides governance, compliance and safeguarding tooling for UK churches and charities. The service is operated by Ministry Memos Ltd, a company registered in England and Wales (company number 17065499). We are registered with the Information Commissioner’s Office (ICO registration number 00014363493).

For any privacy question or to exercise your rights, contact us at info@ministrymemos.com.

What we collect

  • Account details — name, email and organisation, handled by our authentication provider.
  • Governance content you upload — policies, trustee records, risk registers and related documents.
  • Safeguarding records — concern reports and case data, which we store encrypted and logically isolated from other data.
  • Billing details — subscription and payment information, handled by our payment provider (we never store full card numbers).
  • Technical data — log, device and usage information needed to operate and secure the service.

How we use it and our legal basis

  • To provide the service — performance of our contract with you.
  • To analyse policies with AI — to score documents and suggest improvements (see below).
  • To keep the service secure and improve it — our legitimate interests.
  • To take payment — performance of our contract.
  • To meet legal and safeguarding obligations — compliance with a legal obligation and protection of vital interests.

AI policy analysis

When you choose to analyse a policy, its text is sent to our AI provider to generate a compliance score and recommendations. Your content is not used to train AI models and is processed only to return your result. You control when analysis runs.

Service providers (sub-processors)

We share data only with vetted providers who help us run the service, including:

  • Authentication (sign-in and account management)
  • Hosting and database providers (UK/EU region where possible)
  • Encrypted document storage
  • Our AI analysis provider
  • Payment processing
  • Transactional email delivery

We do not sell your data or share it for advertising.

Retention

We keep your data for as long as your account is active and as needed to provide the service. When you close your account we delete or anonymise your data within a reasonable period, except where we must retain it to meet a legal or safeguarding obligation.

Security

We use encryption in transit and at rest, role-based access controls, and additional isolation and encryption for safeguarding records. Access to sensitive safeguarding data is restricted to authorised roles within your organisation.

International transfers

Where data is processed outside the UK, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses.

Your rights

Under UK data protection law you have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. To exercise any of these, email info@ministrymemos.com.

Complaints.If you are unhappy with how we have handled your personal data, please tell us first at the same address. We will acknowledge your complaint within 30 days and tell you the outcome without undue delay. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

Changes to this notice

We may update this notice from time to time. Material changes will be reflected by the “last updated” date above.